Defender for Endpoint Plan 2
$5.2
per user / month (USD)
Add-on (included in M365 E5)
Security Add-ons
Full endpoint detection and response — threat hunting, EDR, automated investigation
Browse all plans
P1 vs P2
| Feature | P1 (in E3) | P2 ($5.20 add-on) |
|---|---|---|
| Next-gen antimalware | ✅ | ✅ |
| Attack surface reduction | ✅ | ✅ |
| Endpoint detection & response (EDR) | ❌ | ✅ |
| Automated investigation & remediation | ❌ | ✅ |
| Threat analytics | ❌ | ✅ |
| Threat hunting | ❌ | ✅ |
| Vulnerability management | ❌ | ✅ |
💡 Plain English: P1 stops known threats. P2 hunts for unknown threats, investigates incidents automatically, and gives your security team forensic timelines.
Frequently Asked Questions
1. Can P2 replace CrowdStrike?
For many organisations, yes. Defender for Endpoint P2 provides comparable EDR capabilities and integrates natively with the rest of the Microsoft security stack (Sentinel, Defender XDR).
Disclaimer
Pricing is in USD (list price, per user, per month) sourced from official Microsoft pricing pages as of April 2026 — pricing, features, and availability are subject to change. Always check the official Microsoft pricing page for the latest information, and contact your Microsoft representative for local pricing, volume discounts, and tailored offers. The views expressed on this page are personal and do not represent official positions of Microsoft.
Detailed visual feature maps by M365 Maps (Aaron Dinnage) · Built by A Guide to Cloud & AI